Privacy Policy
Last updated: August 2026
At Opraiz Foundry, we build intelligence layers and agentic infrastructure. We believe privacy is not a compliance checklist — it is an architectural guarantee. This policy explains what we collect, why, and the rights you hold over it.
1. Who we are
Opraiz Foundry Cognitive Sdn Bhd (“Opraiz Foundry”, “we”, “us”) is a technology company registered in Malaysia with its base in Kuala Lumpur. We are the controller for the personal data described in this policy, unless a separate agreement names us as a processor on behalf of a client.
2. Data we collect
We collect two distinct categories of data:
- Visitor data from this website: contact details you submit (name, work email, company, industry, message), newsletter email addresses, and standard analytics (pages visited, browser, approximate location).
- Deployment data from products you run: essential telemetry such as error traces, OS architecture, agent execution logs, and configuration — collected solely to operate the products and provide the observability layer you rely on.
3. How we use data
- To respond to enquiries, scope engagements and deliver the services you request.
- To send The Foundry Brief newsletter — only if you subscribe, with a one-click unsubscribe on every email.
- To operate, secure, debug and improve our products.
- To meet legal, regulatory and audit obligations.
We do not sell your personal data. We do not use your proprietary codebase or deployment telemetry to train our foundation models without explicit, opt-in enterprise agreements.
4. Legal bases (GDPR)
Where the GDPR applies, we process data on the following bases: performance of a contract (delivering services you request), consent (newsletter subscription), legitimate interest (operating and securing our products and site), and legal obligation.
5. Cookies, analytics & forms
This site uses only essential cookies and, when enabled, privacy-respecting analytics. Enquiry and newsletter submissions are transmitted over TLS to our hosting provider (Vercel, Inc.) and delivered to our inbox or email API provider. Each is a processor acting on our documented instructions. The newsletter system is the only channel that retains contact details for an ongoing purpose.
6. Data sovereignty, security & retention
Your operational data belongs to you. Deployment telemetry is isolated by customer, encrypted in transit and at rest, and purged automatically according to your governance settings. We retain visitor enquiries for as long as needed to serve you, and newsletter data until you unsubscribe. Access to any data is limited to staff with a legitimate need.
7. Healthcare data & compliance
Our healthcare infrastructure operates within HIPAA, GDPR and relevant regional frameworks. Patient intelligence remains on your secure data spine. Where we touch clinical data, Opraiz Foundry acts strictly as a data processor under a data processing agreement, never as the owner of that data.
8. International transfers
Data may be processed by our hosting and email providers outside Malaysia. Where transfers cross borders from a jurisdiction with restrictions (e.g. the EEA or UK), we rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
9. Your rights
Where the GDPR or similar laws apply, you have the right to access, rectify, erase, restrict, object to or port your data, and to withdraw consent at any time. To exercise any right, email hello@opraizfoundry.com. We respond within 30 days. You may also lodge a complaint with your supervisory authority.
10. Children
Our products and this site are not directed at children under 13, and we do not knowingly collect their data.
11. Changes to this policy
We may update this policy as our products and obligations evolve. Material changes will be announced on this page with a revised “Last updated” date.
12. Contact
Questions about privacy? Email hello@opraizfoundry.com or write to Opraiz Foundry Cognitive Sdn Bhd, Kuala Lumpur, Malaysia.